Malicious code in govpkg (PyPI)
Malware
Published
Jul 18, 2026
to the GitHub Advisory Database
•
Updated Jul 28, 2026
Description
Published to the GitHub Advisory Database
Jul 18, 2026
Reviewed
Jul 18, 2026
Last updated
Jul 28, 2026
Source: kam193 (736ef874636ee77d0a5007dea41ad6329e0d5523bfeb5254930985f451a6f6f6)
When using the provided functionality, the package silently downloads a malicious executable and ensures its persistence disguised as a system service. The binary connects with telegra[.]ph.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-07-govpkg
Reasons (based on the campaign):
Downloads and executes a remote executable.
action-hidden-in-lib-usage
persistence
Credit: OpenSSF (source)
References